Advertisement
wavellan

20180914_PHISHING_SCAM_1

Sep 16th, 2018
216
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.50 KB | None | 0 0
  1. Received: from MBX05D-ORD1.mex08.mlsrvr.com (172.29.9.24) by
  2. MBX05C-ORD1.mex08.mlsrvr.com (172.29.9.23) with Microsoft SMTP Server (TLS)
  3. id 15.0.1367.3 via Mailbox Transport; Fri, 14 Sep 2018 14:20:11 -0500
  4. Received: from MBX08D-ORD1.mex08.mlsrvr.com (172.29.9.33) by
  5. MBX05D-ORD1.mex08.mlsrvr.com (172.29.9.24) with Microsoft SMTP Server (TLS)
  6. id 15.0.1367.3; Fri, 14 Sep 2018 14:19:59 -0500
  7. Received: from gate.forward.smtp.ord1d.emailsrvr.com (161.47.34.7) by
  8. MBX08D-ORD1.mex08.mlsrvr.com (172.29.9.33) with Microsoft SMTP Server (TLS)
  9. id 15.0.1367.3 via Frontend Transport; Fri, 14 Sep 2018 14:20:00 -0500
  10. Return-Path: <jenymbz1@mesquitegroup.com>
  11. X-Spam-Threshold: 95
  12. X-Spam-Score: 0
  13. X-Spam-Flag: NO
  14. X-Virus-Scanned: OK
  15. X-Orig-To: REMOVED
  16. X-Originating-Ip: [192.185.145.23]
  17. Authentication-Results: smtp27.gate.ord1d.rsapps.net; iprev=pass policy.iprev="192.185.145.23"; spf=temperror smtp.mailfrom="jenymbz1@mesquitegroup.com" smtp.helo="gateway33.websitewelcome.com"; dkim=fail (signing key too small) header.d=mesquitegroup.com; dmarc=none (p=nil; dis=none) header.from=mesquitegroup.com
  18. X-Suspicious-Flag: YES
  19. X-Classification-ID: 19fee96c-b853-11e8-a337-5254003773d7-1-1
  20. Received: from [192.185.145.23] ([192.185.145.23:47197] helo=gateway33.websitewelcome.com)
  21. by smtp27.gate.ord1d.rsapps.net (envelope-from <jenymbz1@mesquitegroup.com>)
  22. (ecelerity 4.2.38.62370 r(:)) with ESMTPS (cipher=DHE-RSA-AES256-GCM-SHA384)
  23. id 9E/92-16068-1C90C9B5; Fri, 14 Sep 2018 15:19:59 -0400
  24. Received: from cm12.websitewelcome.com (cm12.websitewelcome.com [100.42.49.8])
  25. by gateway33.websitewelcome.com (Postfix) with ESMTP id 2577F18139
  26. for REMOVED; Fri, 14 Sep 2018 14:19:29 -0500 (CDT)
  27. Received: from box5558.bluehost.com ([162.241.218.112])
  28. by cmsmtp with SMTP
  29. id 0tcMgMxWxSjJA0tccgyq1S; Fri, 14 Sep 2018 14:19:28 -0500
  30. X-Authority-Reason: nr=8
  31. DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
  32. d=mesquitegroup.com; s=default; h=Content-Type:MIME-Version:Message-Id:Date:
  33. Subject:Reply-To:To:From:Sender:Cc:Content-Transfer-Encoding:Content-ID:
  34. Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
  35. :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe:
  36. List-Subscribe:List-Post:List-Owner:List-Archive;
  37. bh=fDbVpRJ1NpVMucmP6wnjaS9hl+4bs5JXdcacOVnUSQM=; b=oLFYWsScEicuqzALGURLp8AjSa
  38. /skdRRejenr8OiZm4dYuZ4DAa2U3aceNJnTUEBxYiM7qw2g4gnUzsS0iDopTyQX/RDEGShjmJshnJ
  39. nldthW3jCXveDxez2jAgwgK9Z;
  40. Received: from [37.211.161.164] (port=37916 helo=mail.mesquitegroup.com)
  41. by box5558.bluehost.com with esmtpa (Exim 4.91)
  42. (envelope-from <jenymbz1@mesquitegroup.com>)
  43. id 1g0tcM-000AIx-5L
  44. for REMOVED; Fri, 14 Sep 2018 14:19:02 -0500
  45. From: "jenymbz1" <jenymbz1@mesquitegroup.com>
  46. To: REMOVED
  47. Reply-To: "jenymbz1" <jenymbz1v@yahoo.com>
  48. Subject:
  49. Date: Fri, 14 Sep 2018 19:21:37 +0000
  50. Message-ID: <134965h4g913$ea3301rr$h6as10c0$@mesquitegroup.com>
  51. MIME-Version: 1.0
  52. X-Mailer: Microsoft Outlook 16.0
  53. Thread-Index: eS53dWFjLitoMnFtdW13PTAzZDB5KA==
  54. Content-Language: en-us
  55. X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
  56. X-AntiAbuse: Primary Hostname - box5558.bluehost.com
  57. X-AntiAbuse: Original Domain - REMOVED
  58. X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
  59. X-AntiAbuse: Sender Address Domain - mesquitegroup.com
  60. X-BWhitelist: no
  61. X-Source-IP: 37.211.161.164
  62. X-Source-L: No
  63. X-Exim-ID: 1g0tcM-000AIx-5L
  64. X-Source:
  65. X-Source-Args:
  66. X-Source-Dir:
  67. X-Source-Sender: (mail.mesquitegroup.com) [37.211.161.164]:37916
  68. X-Source-Auth: brandon@mesquitegroup.com
  69. X-Email-Count: 200
  70. X-Source-Cap: bWVzcXVpdDY7bWVzcXVpdDY7Ym94NTU1OC5ibHVlaG9zdC5jb20=
  71. X-Local-Domain: yes
  72. X-MS-Exchange-Organization-Network-Message-Id: 407c1f5d-32e8-48a3-d1fa-08d61a771077
  73. X-MS-Exchange-Organization-AVStamp-Mailbox: SMEXzs^g;1450300;0;This mail has
  74. been scanned by Trend Micro ScanMail for Microsoft Exchange;
  75. X-MS-Exchange-Organization-SCL: 0
  76. X-MS-Exchange-Organization-AuthSource: MBX08D-ORD1.mex08.mlsrvr.com
  77. X-MS-Exchange-Organization-AuthAs: Anonymous
  78. Content-type: multipart/alternative;
  79. boundary="B_3619931226_1118890166"
  80.  
  81. > This message is in MIME format. Since your mail reader does not understand
  82. this format, some or all of this message may not be legible.
  83.  
  84. --B_3619931226_1118890166
  85. Content-type: text/plain;
  86. charset="UTF-8"
  87. Content-transfer-encoding: 7bit
  88.  
  89. Hi William
  90.  
  91.  
  92.  
  93.  
  94.  
  95.  
  96.  
  97. https://goo.gl/BUQ1Ln
  98.  
  99.  
  100.  
  101.  
  102.  
  103.  
  104.  
  105.  
  106.  
  107.  
  108.  
  109.  
  110.  
  111.  
  112. --B_3619931226_1118890166
  113. Content-type: text/html;
  114. charset="UTF-8"
  115. Content-transfer-encoding: quoted-printable
  116.  
  117. <html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-microsof=
  118. t-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" xmlns:m=
  119. =3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http://www.w3.org=
  120. /TR/REC-html40">
  121. <head>
  122. <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dutf-8">
  123. <meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
  124. <style><!--
  125. /* Font Definitions */
  126. @font-face
  127. {font-family:"Cambria Math";
  128. panose-1:2 4 5 3 5 4 6 3 2 4;}
  129. @font-face
  130. {font-family:Calibri;
  131. panose-1:2 15 5 2 2 2 4 3 2 4;}
  132. /* Style Definitions */
  133. p.MsoNormal, li.MsoNormal, div.MsoNormal
  134. {margin:0cm;
  135. margin-bottom:.0001pt;
  136. font-size:11.0pt;
  137. font-family:"Calibri","sans-serif";}
  138. a:link, span.MsoHyperlink
  139. {mso-style-priority:99;
  140. color:#0563C1;
  141. text-decoration:underline;}
  142. a:visited, span.MsoHyperlinkFollowed
  143. {mso-style-priority:99;
  144. color:#954F72;
  145. text-decoration:underline;}
  146. span.EmailStyle17
  147. {mso-style-type:personal-compose;
  148. font-family:"Calibri","sans-serif";
  149. color:windowtext;}
  150. .MsoChpDefault
  151. {mso-style-type:export-only;
  152. font-family:"Calibri","sans-serif";}
  153. @page WordSection1
  154. {size:612.0pt 792.0pt;
  155. margin:2.0cm 42.5pt 2.0cm 3.0cm;}
  156. div.WordSection1
  157. {page:WordSection1;}
  158. --></style><!--[if gte mso 9]><xml>
  159. <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
  160. </xml><![endif]--><!--[if gte mso 9]><xml>
  161. <o:shapelayout v:ext=3D"edit">
  162. <o:idmap v:ext=3D"edit" data=3D"1" />
  163. </o:shapelayout></xml><![endif]-->
  164. </head>
  165. <body link=3D"#0563C1" vlink=3D"#954F72">
  166. <div class=3D"WordSection1">
  167. <p class=3D"MsoNormal"><span style=3D"font-size:10.1pt;font-family:Tahoma">Hi W=
  168. illiam<o:p></o:p></span></p>
  169. <p class=3D"MsoNormal"><span style=3D"font-size:10.1pt;font-family:Tahoma"><o:p=
  170. >&nbsp;</o:p></span></p>
  171. <p class=3D"MsoNormal"><span style=3D"font-size:10.1pt;font-family:Tahoma"><o:p=
  172. >&nbsp;</o:p></span></p>
  173. <p class=3D"MsoNormal"><span style=3D"font-size:10.1pt;font-family:Tahoma"><o:p=
  174. >&nbsp;</o:p></span></p>
  175. <p class=3D"MsoNormal"><span style=3D"font-size:10.1pt;font-family:Tahoma"><a h=
  176. ref=3D"https://goo.gl/BUQ1Ln">https://goo.gl/BUQ1Ln</a><o:p></o:p></span></p>
  177. <p class=3D"MsoNormal"><span style=3D"font-size:10.1pt;font-family:Tahoma"><o:p=
  178. >&nbsp;</o:p></span></p>
  179. <p class=3D"MsoNormal"><span style=3D"font-size:10.1pt;font-family:Tahoma"><o:p=
  180. >&nbsp;</o:p></span></p>
  181. <p class=3D"MsoNormal"><span style=3D"font-size:10.1pt;font-family:Tahoma"><o:p=
  182. >&nbsp;</o:p></span></p>
  183. <p class=3D"MsoNormal"><span style=3D"font-size:10.1pt;font-family:Tahoma"><o:p=
  184. >&nbsp;</o:p></span></p>
  185. <p class=3D"MsoNormal"><span style=3D"font-size:10.1pt;font-family:Tahoma"><o:p=
  186. >&nbsp;</o:p></span></p>
  187. <p class=3D"MsoNormal"><span style=3D"font-size:10.1pt;font-family:Tahoma"><o:p=
  188. ></o:p></span></p>
  189. <p class=3D"MsoNormal"><span style=3D"font-size:10.1pt;font-family:Tahoma"><o:p=
  190. >&nbsp;</o:p></span></p>
  191. </div>
  192. </body>
  193. </html>
  194.  
  195.  
  196. --B_3619931226_1118890166--
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement